Requirement 0002 (Part One: Governance, section 1.2.1 Whole of Government Protective Security Roles; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority complies with all Protective Security Directions. The Home Affairs Secretary may issue a Direction to manage an unacceptable risk; Directions bind Accountable Authorities of PGPA Act entities, flow to third parties bound by deeds, are notified to CSOs and CISOs and are folded into the next release (Directions 001-2023 to 004-2025 and 001-2026 so far). The security plan must record how Directions are implemented.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.